Privacy notice

How ChatterLab handles data

Who is responsible

The controller for the data described here is SRI Group BV, Korte Gasthuisstraat 18 bus 301, 2000 Antwerpen, Belgium, enterprise number 1037.052.239, which runs ChatterLab. For any question or request about your data, write to management@sri-group.eu.

Two kinds of people

Customers create an account, build agents and pay for a plan. Visitors talk to an agent on a customer’s website. Customers are the controllers of what their visitors say; ChatterLab processes it on the customer’s behalf.

What we store

  • Account. Your name, email address and sign-in identity, held by our authentication provider, and the workspace and agents you create.
  • Knowledge. The files, pages and text you give an agent, the passages they are split into, and a numerical representation of each passage used to find relevant ones.
  • Conversations. Every message a visitor sends and every answer an agent gives, with the model used, the passages it drew on, a confidence score and any rating the visitor left. A random identifier, made in the visitor’s browser when they first send a message or a file and kept only until the tab is closed, holds one visit’s messages and files together; it is not linked to a person unless the visitor leaves their details in the contact form or opens a ticket, below.
  • The chat button. On a site that passes its visitors’ consent, and only while the customer has switched on its greeting or second message, the button keeps a small record of the visit in the browser until the tab is closed: when the visit began, how many pages were seen and which message was shown. It times the second message and is never sent to us. How often the chat is opened is counted per hour, with nothing that identifies a visitor, and each conversation records whether the button or one of its messages opened it.
  • Files visitors send. Where a customer allows it, a document a visitor attaches to a question, and the text read from it, kept for 30 days. After that only its name stays with the conversation.
  • Contact details visitors leave. Where a customer switches on the chat’s contact form, what the visitor enters in it (a name, an email address, a phone number or a company, as the customer chooses), whether they want news and offers, the words they were shown and the page they were on. They are e-mailed to the addresses the customer names and kept for 3 years.
  • Tickets. Where a customer switches on tickets, the e-mail address, name and question a visitor leaves for the customer’s team, and the page they were on. The visitor is sent one confirmation and the team’s answers by e-mail. The visitor’s replies by e-mail are received and added to the ticket, as is what the team writes, including notes only the team sees. A received mail is kept as its text; its attachments are not.
  • Usage and billing. Message counts, tokens and credits per month, and a reference to your subscription. Card details never reach us; they are handled by our payment provider.
  • Audit trail. A record of significant events, such as an agent created, a source added or a plan changed, kept for 24 months, as the EU AI Act requires at least six.
  • Abuse protection. The public chat endpoints are rate-limited per visitor address. Only a fingerprint of the address is stored, for one day. It is made with a key that changes every day and is deleted minutes after its day ends; without that key the fingerprint cannot be turned back into the address. Like anything we delete, the key remains for a while in our database host’s backups.

Who processes it

  • Hosting: Vercel, in Frankfurt. Every request to the application passes through it, with the address it came from.
  • Database and files: Neon (Postgres) and Cloudflare R2, both in EU regions with the EU jurisdiction setting on storage.
  • Answers: Cortecs, an EU-hosted model gateway. The passages an answer draws on, the recent conversation and any file the visitor sent with the question are sent to it for each reply.
  • Passage representations: OpenAI’s embedding service, in the United States, under its data-processing terms; API data is not used to train its models. The text of each passage is sent to it when a source is added or retrained, and the text of each question when it is asked, since a question has to be represented the same way to be matched. With e-mail, below, it is one of the two steps that run outside the EU.
  • E-mail: Resend, which sends the reports and the contact details a visitor leaves to the addresses a customer enters, sends the mail about tickets, and receives the replies to it. Resend processes mail in the United States, under the EU-US Data Privacy Framework and standard contractual clauses; the mail itself leaves from, and arrives at, servers in the EU (Ireland).
  • Sign-in: Clerk. Payments: Stripe, including EU VAT handling.

How long

Knowledge and conversations stay until the customer deletes the source, the agent, or the account; deleting an agent removes its conversations and every uploaded file. Usage records stay with the account for billing. Files visitors send, and the text read from them, are deleted after 30 days, or sooner with their conversation. Contact details visitors leave are deleted after 3 years, or sooner with their conversation or when the customer deletes them. A ticket is deleted 2 years after it was solved, or sooner with its conversation or when the customer deletes it; one that is never solved stays until the customer deletes it. The audit trail is deleted after 24 months. Rate-limit hashes are deleted after a day.

Your rights

Under the GDPR you can ask what we hold about you, have it corrected or deleted, receive a copy, and object to or restrict its processing. Visitors should ask the website they were talking to, which controls that data; we help that customer answer. Anyone can also complain to their national data-protection authority.

Changes

This notice is updated when the product changes what it stores or who processes it. The date on the footer is the last update.